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Abstract 



It is shown that the optimum strategy of the eavesdropper, as described in the 
preceding paper, can be expressed in terms of a quantum circuit in a way which makes 
it obvious why certain parameters take on particular values, and why obtaining infor- 
mation in one basis gives rise to noise in the conjugate basis. 

O 

i> ■ 1 Introduction 

The preceding paper Jl| discusses the maximum information which an eavesdropper, Eve, 
can obtain for a given error rate between Alice, who sends signals, and Bob, their legitimate 
recipient, in the context of the BB84 cryptographic scheme |2j. In the present paper we show 
that Eve's optimum strategy, discussed in Sec. Ill of the preceding paper, can be embodied 
in a simple quantum circuit, of the type proposed for quantum computation 0, together 
with appropriate initial states of the two qubits which constitute Eve's probe, and suitable 
final measurements. 

The quantum circuit is extremely simple: it involves only two gates, of the controlled- 
not variety, although adding a third gate could be advantageous under some circumstances 
(discussed towards the end of Sec. |3|). When it is analyzed using the same consistent history 
methods we used earlier Q to simplify the final Fourier transform in Shor's factorization 
algorithm |J, it is immediately obvious how the parameters in Eve's initial state are related 
to the error rates, both errors in the transmission from Alice to Bob, and the errors which 
determine the mutual information between Alice and Eve. 

The results of the preceding paper which are essential for understanding the present one 
are summarized in Sec. || below. The quantum circuit is described in analyzed in Sec. [3|, and 
a brief summary is presented in Sec. [|. 
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2 Errors and Information 

In the BB84 scheme, Alice transmits a signal using a qubit described by a two-dimensional 
Hilbert space; for example, the polarization of a photon, or the spin of a spin half particle. 
The kets \x) and \y) form an orthonormal basis of this space, and 

\y) = (l*> + |y))/A l«) = (k> - |y»/V2, (i) 

form an alternative (conjugate) basis. Alice chooses one of these bases at random, and then 
transmits one of the basis vectors, also chosen at random. Her qubit, hereafter denoted by 
a, is intercepted by Eve and made to interact with a probe consisting of two qubits, which 
we shall call e and /. After this, Eve sends a on to Bob, who measures it in one of the two 
bases, again chosen at random. Eventually Alice announces publicly the basis she used for 
transmission of the signal, and in those cases in which Bob measured in the same basis (the 
other cases are of no interest, for Alice and Bob discard the results), Eve, who now knows 
the basis Alice employed, measures the qubits in her probe in order to estimate which signal 
Alice sent. 

In Sec. II of the preceding paper it was shown that the average information (in the 
Shannon sense) I xy which Eve obtains about Alice's signal when the latter uses the xy basis 
is bounded by 
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where 

<f>{z) = (1 + z) ln(l + z ) + (l- z ) hi(l - z), (3) 

and D uv is the error rate produced by the interaction with Eve's probe when Alice transmits 
and Bob measures in the uv basis. Similarly, when Alice sends a signal in the uv basis, the 
average information I uv which Eve can gain is bounded by a similar inequality 
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(4) 
with D xy the error rate from Alice to Bob when they employ the xy basis. 



3 Quantum Circuit 

The quantum circuit used in Eve's optimum strategy is shown in Fig. [l|. The three horizontal 
lines represent three qubits thought of as moving from left to right as time increases. The 
top line is Alice's qubit a on its way to Bob, while the two lower lines show qubits e and / 
representing Eve's probe. These interact with Alice's qubit through two controlled-not gates, 
labeled 1 and 2 and indicated by solid vertical lines. The dashed vertical lines indicate where 
the qubits are at two specific times which we will want to refer to later. 

The two diagrams in Fig. [I] represent the same quantum circuit, but show its action 
in two different bases: the xy basis in (a) and the uv basis in (b). By xy basis we now 
mean the basis of the full eight-dimensional Hilbert space corresponding to qubits a, e, and 
/, with each qubit in either an \x) or a \y) state. Thus the basis vectors are of the form 
\aef) = \xxy), \xyx), and so forth. Similarly, the uv basis is constituted by vectors of the 



form \aef) = \vuv), and so forth; each of the qubits is in either the state \u) or the state \v), 
where these are related to |x) and \y) through ([TJ). 

In Fig. |l|(a), the xy basis, gate 1 is a unitary transformation which when applied to qubits 
a and e, with the left letter in each ket referring to a and the right to e, yields 

\xx) -> \xx), \xy) -> \xy), \yx) -> \yy), \yy) -> |yx). (5) 

That is, if a is in state \y), e is flipped from \x) to |y) or vice versa, whereas if a is in state 
\x), e remains unchanged; in either case, a retains its original value. Such a gate is called 
"controlled-not" , because flipping a bit corresponds to logical negation, and whether or not 
the taryet qubit e is flipped depends on the state of the control qubit a. Note that / is not 
involved in gate 1, so (||) can be extended to the eight basis vectors of the full Hilbert space 
by inserting a third letter in each of the kets to represent the state of /, the same letter on 
each side of the arrow: \yxx) — > \yyx), \yxy) — > \yyy), and so forth. 

Gate 2 in Fig. |l](a) is another controlled-not operation, but now / is the control qubit 
and a the target qubit, whereas e is not involved (as indicated by the absence of any symbol 
at the intersection of its line with the vertical line representing the gate). The action of gate 
1 followed by gate 2 results in the following unitary transformation on the xy basis vectors: 

\xxx) — > \xxx), \xxy) — ► \yxy), \xyx) — > \xyx), \xyy) — > \yyy), 

\yxx) -> \yyx), \yxy) -> \xyy), \yyx) -> \yxx), \yyy) -» \xxy). (6) 

If instead of the xy basis, the uv basis, see ([TJ), is employed for all three qubits, the 
same circuit, corresponding to the same unitary transformation (§), takes the form shown in 
Fig. [TJ(b) . The reason is that if both qubits involved in a controlled-not gate are changed from 
the xy to the uv basis, the action of the gate can again be represented as a controlled-not, 
but with the control and taryet qubits interchanyed, as the reader can easily verify using (|TJ) . 
Thus (|5]) is equivalent, again with qubit a on the left and e on the right, to 

\uu) — > \uu), \uv) — y \vv), \vu) — > \vu), \vv) — > \uv), (7) 

as can be checked by employing ([!]) with (^|). The result in the uv basis of the two gates 
acting in succession can be worked out either by combining (|T|) with (|S|) or, more simply, by 
employing (0) followed by the corresponding transformation for gate 2 in Fig. |](b). 

The following is then an optimum strategy for Eve. She prepares qubits e and / in initial 

states 



\e ) = Jl- A uv \x) + JA uv \y) = Jl - D uv \u) + JD uv \v) 



\fo) = ^l-D xy \x) + ^/D xy \y) = ^l-A xy \u} + ^jA xy \v}, (8) 

where, with w = uv or xy, A w and D w are related through the formulas: 

1 rrr—, ztt „ 1 



We assume, for convenience, that both quantities are between and 1/2, so that (||) defines 
one quadrant of a circle of radius 1/2 centered at (1/2, 1/2) in the (D w , A w ) plane. It is easy 
to check that the second equality in each line in (|8]) is consistent with (P and (|9|). 



After the initial preparation, qubits e and / interact with Alice's qubit a in the quantum 
circuit of Fig. [TJ, and Eve allows a to go on to Bob while storing e and / until Alice announces 
the basis in which the signal was transmitted. Then Eve measures both qubits e and / in 
the basis (xy or uv) announced by Alice. 

One can check that this is an optimum strategy by applying the unitary transformation 
(|) to the initial state 

I a) ® |eo) ® |/o), (10) 

expressed as a linear combination of the xy basis states, to obtain \X) if \a) = \x) and \Y) 
if | a) = \y), in the notation of the preceding paper, and \U) and | V) by means of: 



\U) = (\X) + \Y))/V2, \V) = (\X}-\Y))/V2. (11) 

Then using the projectors {E\} and {F\} defined in Sec. Ill of the preceding paper, one can 
verify that the conditions given there (in Sec. II) for saturating the bounds (0) and (f£|) are 
satisfied. 

However, we shall use an alternative approach, which yields more insight into the choice 
of coefficients in (|j): we shall calculate the error rates and mutual information directly from 
the quantum circuit in Fig. [I], and verify that (0) and (ffl) are satisfied as equalities. Let us 
begin with the situation in which Alice announces, and Eve measures in, the xy basis, which 
can best be understood using Fig. |l](a). First consider the case in which D xy and A uv — note 
that Eve can choose them independently — are both equal to zero, so that both e and / are 
initially in the state \x), (U). Then gate 1 simply copies qubit a, \x) or \y), to qubit e, so that 
by measuring e in the xy basis, Eve knows precisely which signal Alice sent. Furthermore, 
since / is in the state \x), qubit a remains unchanged on its way from Alice to Bob, so Eve's 
intervention causes no error. 

If A uv = but D xy is positive, Eve will again be able to determine which signal Alice 
sent by measuring e. However, measuring / will yield \y) with probability D xy and \x) with 
probability 1 — D xy . Since / is the control qubit for gate 2, if it is in state \y), an error will 
be produced in the transmission from Alice to Bob, while if it is in state \x), there will be 
no error. Hence Eve's measurement of /, while it tells her nothing about which signal Alice 
sent, shows her whether or not, in this particular case, Bob's measurement yielded the same 
or the opposite result from what Alice transmitted. 

In the preceding paragraph we used a process of retrodiction, in which we inferred the 
prior state of qubit / from Eve's measurement. This can lead to quantum paradoxes when 
it is not used in the proper way, but in the present context it can be justified, just as in 
||, by using an appropriate framework or family of consistent histories ||. However, rather 
than employing retrodiction for qubit e as well, it is more straightforward to adopt at the 
outset an appropriate consistent family, which we shall call the xy framework, based upon 
all three qubits being in either an \x) or a \y) state at a time t\ shortly after to, when (|8|) 
applies, but before qubits a and e reach the first gate, see Fig. [I], and at all later times as 
well 0. In this framework, e at time t\ is in the state \y) with probability A uv , and in \x) 
with probability 1 — A uv , the absolute squares of the corresponding coefficients in (|j), while 
for / these probabilities are D xy and 1 — D xy . As long as we are using the xy framework, 
these probabilities can be thought of in the same way as in a classical stochastic theory || . 

Because qubit / at t\, and thus at all later times until it is measured, is in state \y) with 
probability D xy , this is also the probability of an error if Alice is transmitting to Bob in the 



xy mode, as noted earlier. Next let us consider qubit e. The results of Eve's measurement, 
which is the value e has when it leaves gate 1, will coincide with the initial value of a only 
if at t\ e is in the state \x). Otherwise the measured value will be the reverse of what Alice 
transmits. Thus if one thinks of gate 1 as part of a communication channel from Alice (qubit 
a) to Eve (qubit e), it is a noisy channel with a probability A uv that a bit will be flipped. 
The mutual information I xy associated with such a channel is easily computed, assuming 
that Alice transmits \x) or \y) with equal probability, and is given by the right side of (0). 

To understand what happens when Alice sends a signal, and Eve makes her measure- 
ments, in the uv basis, we use Fig. |I](b) and an alternative consistent family, which we call 
the uv framework, in which all three qubits are in state \u) or \v) at t\ and all later times 
||. Then in this framework, e is in state \v) with probability D uv , and \u) with probability 
1 — D uv , at ti, see (§). For / the corresponding probabilities are A xy and 1 — A xy . As e 
is now the control qubit for gate 1, Fig. |l|(b), it is at once obvious that when e is in state 
\v), there will be an error in the transmission from Alice to Bob when they use the uv basis. 
Thus the error rate in this basis is D uv , the probability that e is in state \v) at t%, and hence 
at later times as well. Also by measuring e (in the uv basis) Alice can determine whether 
or not such an error has occurred. However, measuring e tells her nothing about whether 
Alice sent a \u) or a \v). To obtain this information, she must measure qubit /. The task 
is a bit more complicated than in the case of the xy basis considered earlier, because qubit 
a may have been flipped through its interaction with e before it is copied to /. However, 
since she also measures e, Eve can easily correct for this effect. Consequently, the noise in 
the channel between Alice (qubit a) and Eve (qubit / corrected by e) is determined by the 
uncertainty in the value of / at t\] a bit passing from Alice to Eve through this channel 
will be flipped with probability A xy , the probability that / is in state \v) at t\. Again, the 
mutual information I uv for such a channel is easily computed, and is given by the right side 
of (§. 

Consequently, one sees that the error rates produced by Eve's employing the initial states 
in (|) are, indeed, D xy and D uv in the xy and uv bases, respectively, whereas the appropriate 
mutual information in each case saturates the corresponding bound, (Q) or (B). This shows 
that Eve's strategy employing the gates in Fig. [I] is, indeed, optimal. Furthermore, one can 
understand how Eve faces a trade-off between gaining information when Alice sends in one 
mode, and creating errors when Alice uses the other mode. If Alice only employed the xy 
mode, Eve would, of course, set both D xy and A uv equal to zero, as this would cause no 
errors in the transmission from Alice to Bob, and produce a perfect copy of Alice's signal in 
qubit e. However, A uv = is equivalent, (§), to D uv = 1/2, so that obtaining the maximum 
possible information about the xy transmission produces a large number of errors in the uv 
mode. Similarly, setting D xy = 0, while it produces no errors when Alice transmits in the xy 
mode, has the consequence the A uv = 1/2, which means that Eve can extract no information 
whatever when Alice transmits in the uv mode. 

Eve's strategy as described above requires that she store both qubits e and / while 
waiting for Alice to announce the basis used in sending the signal. Since the "storage costs" 
of preserving the qubits against decoherence, should there be a long delay, could be high, 
it is worth noting, as was pointed out in the preceding paper, that only one qubit needs to 
be preserved if Eve just wants to estimate which signal Alice sent, and is not interested in 
keeping track of whether an error occurred in the transmission from Alice to Bob. From 



Fig. |l|(a) it is evident that in the xy case, qubit / could be discarded after it emerges from 
gate 2, since Eve only uses e to gain information about Alice's signal. However, this would 
not work for the uv basis, where the information of interest is contained in the correlation 
between the two qubits. There are, nonetheless, two obvious strategies available to Eve. She 
can measure qubit / in the uv basis immediately after it emerges from gate 2, and record the 
value in her notebook, while preserving qubit e for later analysis. If Alice later announces 
that she used the xy basis, Eve ignores the record in her notebook, and measures e in the xy 
basis. If, on the other hand, the basis turns out to be uv, Eve measures e in that basis and 
uses it to correct the / value she measured earlier. An alterative approach is to add a third 
gate to the circuit in Fig. [I], a controlled-not in which e is the control and / the target in 
the xy basis (and, of course, the reverse in the uv basis). After it passes through this third 
gate, Eve discards qubit / and retains qubit e for later measurement in whichever basis is 
appropriate; this is equivalent to the approach employed in the preceding paper. 

The use of the quantum circuit does not solve the problem of whether Eve's optimum 
strategy is essentially unique. One can show that interchanging (a) and (b) in Fig. |l], that 
is, employing the circuit in (a) for the uv basis and that in (b) for the xy basis, is equivalent 
to the original scheme preceded and followed by unitary transformations on the qubits of 
Eve's probe, so that it is not different in any essential way. However, this obviously does not 
settle the question of uniqueness. 

4 Conclusion 

We have shown that Eve's optimum strategy can be represented by a simple quantum circuit 
involving two controlled-not gates, along with the preparation of the two qubits of her probe 
in suitable initial states, and their later measurement in the same basis announced by Alice. 
In this circuit, the function of each qubit of the probe is clearly distinguished. For example, 
in the xy basis, qubit e is employed for extracting information about the signal Alice sends, 
while / creates errors in the transmission from Alice to Bob. While these errors can be 
reduced to zero by Eve's choice of a suitable initial state for /, this choice makes it impossible 
for her to obtain any information when Alice transmits in the uv basis, for which Eve must 
extract the information using /. 

While the use of the quantum circuit provides one with a certain amount of insight into 
eavesdropping strategies, it does not by itself provide a proof that the strategy is optimal, 
for which one needs the bounds derived in the preceding paper, nor does it show that there 
is a unique optimal strategy. 
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Figure 1: Quantum circuit representing the interaction of Eve's probe, qubits e and /, with 
Alice's qubit a, in (a) the xy basis and (b) the uv basis. 
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